GDPR & EU AI Act
Written for the people who have to sign things off: legal, compliance, IT and procurement. It covers our role, our legal bases, where data goes, and how the EU AI Act applies to what we build.
Nothing here is legal advice about your own obligations. It is a statement of ours.
Last updated: August 11th, 2026
Part A
01 · Who is responsible for what
The most important thing to establish is which of us is doing what with the data.
Website, demo requests, and accounts
We decide what to collect and why: your name, work email, company, job title, and how you use the platform. This is covered in our Privacy Policy. Privacy Policy
Your Company Brain and connected systems
You decide what data enters the platform and what the agents do with it. We process it on your documented instructions and for no other purpose.
That distinction matters in practice. It means we do not decide what your agents do with personal data, we do not repurpose your data for our own ends, and we do not answer requests from your employees or customers about their data. We route them to you and help you answer.
The terms of that processing relationship are set out in a Data Processing Agreement, which reflects the requirements of Article 28 GDPR: subject matter and duration, purpose, categories of data and data subject, confidentiality, security measures, subprocessing, assistance with rights requests, and deletion or return of data. It is available to clients on request at [email protected].
02 · Applicable law
We process personal data subject to:
Where the two regimes differ, we apply the standard that offers the higher level of protection.
03 · What we process, and on what legal basis
As controller: website visitors, prospects and account holders
| Purpose | Data | Legal basis |
|---|---|---|
| Providing and administering your account | Name, email, company, role, usage data | Contract (Art. 6(1)(b)) |
| Billing and payment | Billing details, invoicing data | Contract / legal obligation |
| Support and communication | Contact details, correspondence | Contract / legitimate interests |
| Product analytics and improvement | Usage and technical data | Legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention, abuse monitoring | Technical and access data | Legitimate interests |
| Marketing communications | Contact details | Consent (Art. 6(1)(a)), withdrawable at any time |
| Legal and regulatory compliance | As required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we assess that interest against the rights and freedoms of the individuals concerned.
As processor: data inside your Company Brain and your agent workflows
We process whatever categories of personal data you choose to place in the platform or expose through your connected systems. Depending on the workflows you build, that may include employee, candidate, customer or supplier data. Establishing the legal basis for that processing is your responsibility as controller. Ours is to process it only as instructed, and to give you the controls to do so lawfully.
04 · Your uploaded data
Not ours, not anyone's, not general-purpose models, not fine-tuning. This is binding on us and on the model providers we use.
Each client's knowledge base, integrations and agent workflows are logically separated.
Your content is yours. Our licence to it exists solely to deliver the service and ends when the relationship does.
Data is read from and written to the platforms you already use, inheriting the role-based permissions configured there. We do not build a parallel copy of your business inside a Growy database.
05 · Subprocessors
We use a limited set of subprocessors. Each is bound by a written contract imposing data protection obligations no less protective than our own, and each is assessed before engagement and reviewed thereafter.
They fall into these categories:
The current named subprocessor list forms part of our Data Processing Agreement and is available on request at [email protected]. We inform clients of material changes to our subprocessors.
06 · Model providers and your data
When an agent or assistant runs, the relevant content is sent to a model provider to generate the output.
Model selection is made per task on capability, reliability and cost. We review providers on an ongoing basis and may change them. Material changes affecting how client data is processed are communicated to affected clients.
07 · International transfers
Personal data may be processed outside the UK or EEA, principally because some model and infrastructure providers operate in the United States.
Where that happens, transfers are made under an appropriate Article 46 safeguard: Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved, or under an adequacy decision where one applies. We assess transfers and apply supplementary technical measures where required, principally encryption in transit and at rest.
08 · Retention
Retention periods for each category of data are set out in our Privacy Policy.
For data we process on your behalf as processor, retention is governed by your instructions and your agreement with us. On termination you may export your content in a commonly used, machine-readable format. After 30 days we delete it from live systems, with backup copies expiring on our standard backup cycle.
Deletion requests are actioned within 30 days.
09 · Individual rights
Where we are the controller of your data, you may exercise your rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent by writing to [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend. You also have the right to complain to a supervisory authority: the ICO in the UK, or your national authority in the EEA.
That client is the controller and you should contact them directly. We assist our clients in responding: the platform allows client administrators to locate, export, correct and delete records, and we support them where a request cannot be fulfilled through the interface alone.
10 · Automated decision-making
Article 22 GDPR restricts decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Growy agents are designed so that decisions of that kind are not made by the agent. Where a workflow touches an outcome affecting an individual: a hiring decision, a disciplinary step, a performance assessment, an eligibility determination: the platform is configured so that a person makes the decision, with the agent preparing, summarising or presenting information for that person to act on.
Our node builder supports mandatory approval steps, escalation paths and confidence thresholds precisely so that this line is enforced in the workflow itself rather than only stated as a policy. Where a client wishes to configure a workflow that could approach Article 22 territory, we raise it during scoping.
11 · Security
Encryption in transit and at rest, role-based access control, logically separated client environments, workflow and node-level audit logging, and permissions inherited from your source systems.
Access controls and safeguards, explained end to end.
12 · Personal data breaches
As processor
If we become aware of a personal data breach affecting data we process on your behalf, we notify you without undue delay, with the information you need to meet your own obligations as controller.
As controller
We notify the relevant supervisory authority within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, and we notify affected individuals without undue delay where that risk is high, in line with Articles 33 and 34.
13 · Data protection impact assessments
Where your use of Growy requires a DPIA: likely for systematic monitoring, large-scale processing of special category data, or workflows involving employee data, we provide the information you need to complete it: data flows, subprocessors, retention, security measures, and the specific role of AI in the workflow. Request this at [email protected].
Part B
14 · Where we sit in the Act
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. It matters which role each party holds.
We develop and place the Growy platform on the market under our own name.
When you configure agents and run them in your organisation, you use an AI system under your own authority. Deployer obligations sit with you. We build the platform so that you can meet them.
Anthropic, OpenAI and Google carry the GPAI obligations for the models themselves, which have applied since 2 August 2025.
We are explicit about this split because vendors who blur it tend to be overstating what they have taken off your plate.
15 · Risk classification
Most Growy deployments: operational reporting, document retrieval, internal coordination, administrative workflow, supplier and sales operations: sit in the minimal risk category, with limited risk transparency obligations applying wherever a person interacts with an AI system or receives AI-generated content.
Some workflows require more care. Annex III of the Act designates certain employment and worker-management uses as high risk, including recruitment, candidate screening and evaluation, allocation of tasks, and monitoring or evaluation of performance. Growy is used in HR and onboarding contexts, so this is live territory rather than theoretical.
Our approach
We do not build systems for biometric identification or categorisation, emotion inference in workplaces or education, social scoring, predictive policing, or any practice prohibited under Article 5, which has applied since 2 February 2025.
16 · Transparency
17 · AI literacy
Providers and deployers must take measures to ensure a sufficient level of AI literacy among the staff operating AI systems on their behalf.
Internally, our teams are trained on the capabilities, limitations and risks of the systems we build. For clients, every deployment includes handover covering what the agent does, where it can fail, where human judgement is required, and how to pause or override it. We treat this as part of delivery, not an optional extra.
18 · Compliance timeline
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices (Art. 5); AI literacy (Art. 4) |
| 2 August 2025 | Obligations for general-purpose AI models |
| 2 August 2026 | Article 50 transparency obligations; general application |
| 2 December 2026 | Art. 50(2) marking for systems already on the market; new prohibitions added by the Omnibus |
| 2 December 2027 | High-risk obligations for stand-alone Annex III systems |
| 2 August 2028 | High-risk obligations for AI embedded in Annex I regulated products |
The deferral of the high-risk deadlines changed the timing, not the substance. We build against the requirements now rather than treating 2027 as distance.
19 · Documentation available to clients
Request any of these at [email protected].
20 · What we ask of you
As controller and deployer, you are responsible for:
21 · Contact